1. *Recon: read /robots.txt β it discloses /dev-portal. Why:* recon maps the attack surface.
2. *Enumerate: /dev-portal has a login. Exploit:* SQLi auth bypass with ' OR '1'='1 in the password logs you in as a low-priv dev.
3. *Privesc: the session has a role=dev cookie; set role=admin to reach /admin. Why:* chaining a weak authz check after initial access escalates privilege.
4. /admin prints the flag.
Lesson: methodical chaining turns small flaws into full compromise.